Skip to finding
important · Zero-click — Edge

Cisco confirms active exploitation of one-email root execution on Secure Email Gateway.

Affects

Cisco Secure Email Gateway, physical and virtual email-security appliances running Cisco AsyncOS.

A crafted message delivered to an affected physical, virtual, or Cisco-hosted gateway is parsed without authentication or recipient interaction; malicious SQL reaches operating-system command execution as root.

Detail and 1 source

Cisco publishes fixed release boundaries, and post-exploitation access can include cluster SSH keys or removal of local evidence.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 20, 2026